<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CMC</journal-id>
<journal-id journal-id-type="nlm-ta">CMC</journal-id>
<journal-id journal-id-type="publisher-id">CMC</journal-id>
<journal-title-group>
<journal-title>Computers, Materials &#x0026; Continua</journal-title>
</journal-title-group>
<issn pub-type="epub">1546-2226</issn>
<issn pub-type="ppub">1546-2218</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">58963</article-id>
<article-id pub-id-type="doi">10.32604/cmc.2025.058963</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Machine Learning-Based Detection and Selective Mitigation of Denial-of-Service Attacks in Wireless Sensor Networks</article-title>
<alt-title alt-title-type="left-running-head">Machine Learning-Based Detection and Selective Mitigation of Denial-of-Service Attacks in Wireless Sensor Networks</alt-title>
<alt-title alt-title-type="right-running-head">Machine Learning-Based Detection and Selective Mitigation of Denial-of-Service Attacks in Wireless Sensor Networks</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Joo</surname><given-names>Soyoung</given-names></name><xref ref-type="author-notes" rid="afn1">#</xref></contrib>
<contrib id="author-2" contrib-type="author">
<name name-style="western"><surname>Park</surname><given-names>So-Hyun</given-names></name><xref ref-type="author-notes" rid="afn1">#</xref></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Shim</surname><given-names>Hye-Yeon</given-names></name></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Oh</surname><given-names>Ye-Sol</given-names></name></contrib>
<contrib id="author-5" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Lee</surname><given-names>Il-Gu</given-names></name><xref rid="cor1" ref-type="corresp">&#x002A;</xref><email>iglee@sungshin.ac.kr</email></contrib>
<aff id="aff-1"><institution>Department of Future Convergence Technology Engineering, Sungshin Women&#x2019;s University</institution>, <addr-line>Seoul, 02844</addr-line>, <country>Republic of Korea</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Il-Gu Lee. Email: <email>iglee@sungshin.ac.kr</email></corresp>
<fn id="afn1">
<p>#Co-first authors</p>
</fn>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2025</year>
</pub-date>
<pub-date date-type="pub" publication-format="electronic">
<day>17</day><month>02</month><year>2025</year>
</pub-date>
<volume>82</volume>
<issue>2</issue>
<fpage>2475</fpage>
<lpage>2494</lpage>
<history>
<date date-type="received">
<day>25</day>
<month>9</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>13</day>
<month>12</month>
<year>2024</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 The Authors.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Published by Tech Science Press.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CMC_58963.pdf"></self-uri>
<abstract>
<p>As the density of wireless networks increases globally, the vulnerability of overlapped dense wireless communications to interference by hidden nodes and denial-of-service (DoS) attacks is becoming more apparent. There exists a gap in research on the detection and response to attacks on Medium Access Control (MAC) mechanisms themselves, which would lead to service outages between nodes. Classifying exploitation and deceptive jamming attacks on control mechanisms is particularly challengingdue to their resemblance to normal heavy communication patterns. Accordingly, this paper proposes a machine learning-based selective attack mitigation model that detects DoS attacks on wireless networks by monitoring packet log data. Based on the type of detected attack, it implements effective corresponding mitigation techniques to restore performance to nodes whose availability has been compromised. Experimental results reveal that the accuracy of the proposed model is 14% higher than that of a baseline anomaly detection model. Further, the appropriate mitigation techniques selected by the proposed system based on the attack type improve the average throughput by more than 440% compared to the case without a response.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Distributed coordinated function mechanism</kwd>
<kwd>jamming attack</kwd>
<kwd>machine learning-based attack detection</kwd>
<kwd>selective attack mitigation model</kwd>
<kwd>selective attack mitigation model</kwd>
<kwd>selfish attack</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Training Industrial Security Specialist for High-Tech Industry</funding-source>
<award-id>RS-2024-00415520</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Korea Institute for Advancement of Technology</funding-source>
<award-id>IITP-2022-RS-2022-00156310</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>As wireless communication is a key technological enabler in nearly all domains, it is vital that its components meet the required performance and security demands. Internet of Things (IoT) and wireless sensor networks (WSNs) are examples of such components, which support various operations using networks of heterogeneous industrial devices connected wirelessly [<xref ref-type="bibr" rid="ref-1">1</xref>&#x2013;<xref ref-type="bibr" rid="ref-3">3</xref>]. IoT networks involving sensor nodes typically operate on battery power, making energy-efficient, low-power communication protocols crucial to meet low-power consumption requirements. In WSNs, protocols such as ZigBee or Institute of Electrical and Electronics Engineers (IEEE) 802.15.4 are commonly used to this end. Additionally, the IEEE 802.11 ah (Wi-Fi HaLow) standard is a Wireless Local Area Network (WLAN) standard designed for long-range communication operating in the sub-1 GHz unlicensed band, excluding the TV white space band, which is used for long-range communication in IoT applications.</p>
<p>IEEE 802.11 standard defines communication protocols for WLAN. Due to its backward compatibility and ongoing development, WLAN technology demonstrates excellent scalability, making it a widely adopted communication technology for wireless devices not only in WSNs but also in IoT networks. In next-generation WLAN standards, reliability has gained increasing significance, becoming as important as communication efficiency. To ensure WLAN reliability, both communication performance and security during the communication process must be considered. Since communication reliability directly affects performance, WLAN security must be addressed to achieve optimal performance and efficiency.</p>
<p>Conventional WLAN technologies have primarily focused on enhancing communication performance and efficiency. IEEE 802.11n standard was developed to achieve high throughput by leveraging multiple-input and multiple-output (MIMO) antenna technology. It can accommodate up to four antennas at both the transmitter and receiver, utilizing up to four spatial streams while supporting beamforming. The IEEE 802.11ac standard increases transmission efficiency by expanding the bandwidth to 160 MHz and improving overall system throughput through downlink multi-user MIMO (MU-MIMO). To address efficiency challenges in dense networks, the IEEE 802.11ax standard introduces orthogonal frequency division multiple access and uplink MU-MIMO, ensuring more efficient use of frequency resources. Most recently, IEEE 802.11be standard incorporates multi-link operation, allowing simultaneous communication over multiple channels, further improving communication efficiency.</p>
<p>Although WLAN security technologies have been extensively researched [<xref ref-type="bibr" rid="ref-4">4</xref>], traditional WLAN designs have focused more on maximizing performance and efficiency than on enhancing security, leaving them vulnerable to potential attacks. This is a critical shortcoming, esecially because WLAN security extends beyond direct techniques like data encryption to include defenses against attacks that exploit system blind spots. For instance, Medium Access Control (MAC) layer header is transmitted without encryption, making it highly vulnerable to attacks that tamper with unprotected data. An attacker can interfere with normal communication by altering critical information in the MAC frame header, such as the STA address, packet number, and duration, to trigger malicious behavior.</p>
<p>Message traffic suffers performance degradation due to interference, collisions, hidden nodes, and deceptive attacks [<xref ref-type="bibr" rid="ref-5">5</xref>&#x2013;<xref ref-type="bibr" rid="ref-8">8</xref>]. To address this, the IEEE 802.11 MAC protocol specifies virtual and physical carrier sensing mechanisms that effectively avoid or mitigate collisions between wireless nodes while competing for channel access. The Carrier Sense Multiple Access with Collision Avoidance (CSMA/CA), an access control technique implemented in the MAC layer, prevents frame collisions based on virtual carrier sensing. To minimize collisions caused by simultaneous data transmissions, stations (STAs) first perform physical carrier sensing to verify the availability of the wireless channel before initiating data transmission. After waiting for a random backoff period, STAs transmit data transmission on idle channels. If the channel is busy, the random waiting time is increased exponentially. This waiting time implemented to avoid collisions is determined by the contention window (CW), which ranges between the minimum (CWmin) and maximum (CWmax) values. STAs with smaller CW values gain access to the medium more quickly. Since CW values are randomly assigned at each instance, fair competition among all STAs attempting to access the medium is maintained in a normal network.</p>
<p>However, channel access mechanisms are susceptible to exploitation attacks that can disrupt nodes&#x2019; ability to communicate with access points (APs) [<xref ref-type="bibr" rid="ref-9">9</xref>]. For example, denial-of-service (DoS) attacks overwhelm target networks with excessive traffic, preventing nodes from accessing the communication medium. DoS attacks typically fall into two categories: <bold>selfish attacks</bold>, where attackers manipulate the backoff counter value to monopolize network resources, and <bold>jamming attacks</bold>, where attackers intentionally transmit continuous noise to interfere with specific devices. These attack types are explored in further detail below.</p>
<p>In a selfish attack, attackers &#x201C;selfishly&#x201D; occupy communication channels with an AP in a WLAN. Such attacks are carried out by manipulating the CW value of a STA. Generally, CWmin is set to 15 (except in the 802.11b standard) and CWmax to 1023. Selfish nodes are attackers that exploit the fair access mechanism by consistently gaining priority access to the medium. All parameters of selfish nodes are configured identically to those of normal nodes, except their CWmin and CWmax values are reduced to ensure lower backoff counter values. This allows them to gain unfair access to the communication medium. As a result, selfish attacks degrade network performance by lowering overall data transmission throughput and reducing network availability by blocking other nodes from acccessing the medium. While the selfish node&#x2019;s individual throughput increases, the overall network throughput suffers significantly.</p>
<p>On the other hand, jamming attacks represent another major threat that compromises the availability of network systems. In fields such as military security, jammers are used to block data communication with external networks and unauthorized users. However, attackers can misuse jammers to launch DoS attacks, disrupting communication signals between legitimate users. Since jamming signals interfere with transmissions from legitimate senders, the signal-to-interference-plus-noise ratio (SINR) deteriorates significantly under such attacks, preventing receivers from correctly decoding transmitted messages.</p>
<p>In energy-constrained environments like WSN and IoT-based networks, DoS attacks pose an even greater threat. If data transmission fails in WLAN, the automatic repeat request mechanism retransmits the data. As a result, persistant DoS attacks not only degrade throughput significantly compared to normal operating conditions but also consume a large amount of the device&#x2019;s energy resources, leading to higher communication costs. Moreover, DoS attacks can escalate into battery depletion attacks, deliberately draining the batteries of sensor and IoT devices that rely solely on battery power. IoT devices are particularly vulnerable not only to jamming attacks that disrupt availability but also to battery depletion attacks that can cause complete system shutdowns. Therefore, detecting jamming attacks is a crucial priority for IoT and WSN environments.</p>
<p>In normal network congestion scenarios, issues such as reduced throughput and availability of STAs can occur naturally, making it challenging to distinguish between regular network congestion and malicious DoS attacks. This is especially true for selfish attacks because nodes&#x2019; CW values are set randomly under normal operation. Similarly, distinguishing between heavy interference caused by environmental factors and intentional jamming attacks can be equally difficult.</p>
<p>Machine learning models offer promising attack detection solutions for detecting such attacks without requiring complex or resource-intensive modifications to the MAC protocol [<xref ref-type="bibr" rid="ref-10">10</xref>]. They have been effectively applied to detect critical attacks, including DoS attacks [<xref ref-type="bibr" rid="ref-11">11</xref>&#x2013;<xref ref-type="bibr" rid="ref-14">14</xref>]. With numerous studies exploring their use in IoT and WSN environments [<xref ref-type="bibr" rid="ref-15">15</xref>&#x2013;<xref ref-type="bibr" rid="ref-18">18</xref>]. In particular, DoS attacks can be identified by analyzing their side effects, such as reduced throughput across multiple nodes, increased delays, and altered signal reception patterns within the network. The behavior of selfish and jamming attacks increases the energy consumption of APs by raising service demands, ultimately blocking multiple connected nodes from communicating.</p>
<p>In this paper, we propose a model for detecting selfish and jamming attacks in IEEE 802.11-based WSNs operating in diverse, overlapping, and large-scale environments. The model addresses these attacks using approproate selective response mitigation techniques. To achieve this, a simplified basic service set environment is considered for each attack, where the machine learning model detects malicious behavior by analyzing communication occupancy frequencies, packet durations, and CW values. This approach enables the application of effective defense mechanisms against detected attacks. Specifically, conflicting numbers of control packets and average throughput are compared to determine the optimal backoff counter value for selfish attack responses. The main contributions of this paper are summarized below:
<list list-type="bullet">
<list-item>
<p><bold>Modeling of Selfish and Jamming Attacks:</bold> Selfish and jamming attacks are modeled in IEEE 802.11-based wireless communication system environments.</p></list-item>
<list-item>
<p><bold>Attack Pattern Analysis:</bold> Attack patterns are distinguished by analyzing the effects of the attacks and the available packet trace log data.</p></list-item>
<list-item>
<p><bold>Machine Learning-Based Attack Detection:</bold> The proposed machine learning attack detection method classifies attacks based on the duration of packet communication, the number of communication repetitions with the AP, and the status of the node&#x2019;s CW value (manipulated <italic>vs.</italic> not-manipulated). Its performance is validated by comparing its attack detection rate with that of a state-of-the-art anomaly detection model.</p></list-item>
<list-item>
<p><bold>Selective Attack Mitigation Model (SAMM):</bold> A novel selective attack mitigation model (SAMM) is proposed that applies appropriate countermeasures based on detected attacks.</p></list-item>
</list></p>
<p>The remainder of this paper is organized as follows. In <xref ref-type="sec" rid="s2">Section 2</xref>, related works on selfish and jamming attacks are reviwed. In <xref ref-type="sec" rid="s3">Section 3</xref>, an overview of the IEEE 802.11 protocol is presented. The simulation environment and attack models are described in <xref ref-type="sec" rid="s4">Section 4</xref>, and SAMM and extant DoS attack detection methods are described in <xref ref-type="sec" rid="s5">Section 5</xref>. In <xref ref-type="sec" rid="s6">Section 6</xref>, the proposed model&#x2019;s performance is validated and its efficiency is assessed. Finally, the paper is concluded in <xref ref-type="sec" rid="s8">Section 8</xref>.</p>
</sec>
<sec id="s2">
<label>2</label>
<title>Related Works</title>
<p>In WLANs, the virtual carrier sense mechanism predicts the state of a channel at any time using a network allocation vector (NAV) by analyzing the duration of the previous frame. Notably, the NAV mechanism is vulnerable to false blocking, virtual jamming, and ready-to-send (RTS)/clear-to-send (CTS) attacks [<xref ref-type="bibr" rid="ref-19">19</xref>]. On the other hand, the physical carrier sense (i.e., clear channel assessment (CCA)) mechanism monitors busy or idle states of channels objectively and continuously and transmits the information to the wireless network&#x2019;s MAC sublayer. This process is vulnerable to DoS attacks that interfere with the availability of other nodes and prevent legitimate users from accessing the channel. This section presents an overview of the most relevant studies on deceptive selfish and jamming DoS attacks and appropriate response methods. There is a variety of research focused on detecting and responding to selfish attacks and jamming attacks individually, but few studies distinguish between these two attacks to detect and respond selectively.</p>
<sec id="s2_1">
<label>2.1</label>
<title>Selfish Attacks</title>
<p>The distributed coordination function (DCF) mechanism, which is a CSMA/CA medium access protocol for WLANs, is vulnerable to selfish backoff attacks [<xref ref-type="bibr" rid="ref-20">20</xref>]. This is because selfish devices can set their backoff timers to very small thresholds, allowing them to access channels more frequently than other devices [<xref ref-type="bibr" rid="ref-21">21</xref>]. The CW size determines the range of the random backoff counter for all devices. Normally, minimum and maximum CW values are fixed within the standard. However, a selfish device can manipulate these values to override its priority. Selfish behaviors can include partial dropping, false accusation, packet dropping, and insufficient transmission power effects [<xref ref-type="bibr" rid="ref-22">22</xref>].</p>
<p>Several studies have analyzed selfish attacks, and their countermeasures are largely governed by game theoretic considerations related to managing routing paths, energy usage, and node confidence values. Konorski et al. proposed a game theory-based approach to handle greedy and honest nodes, enabling the latter to overcome their throughput disadvantages, especially with increasing number of nodes. Their simulation results demonstrated that the throughput of greedy nodes gradually decreased because small manipulations of the CW parameter were equally effective for disruptions and remedies [<xref ref-type="bibr" rid="ref-20">20</xref>].</p>
<p>Fihri et al. proposed a support vector machine-based nonlinear classifier to detect backoff manipulation attacks. The model exhibited the shortest execution times among machine learning classifiers, especially when supplied with radial basis function kernel classifiers. Moreover, it exhibited the lowest computational complexity [<xref ref-type="bibr" rid="ref-23">23</xref>]. Kim et al. proposed a method for detecting selfish attacks by mathematically analyzing selfish backoff attacks using logistic classifiers [<xref ref-type="bibr" rid="ref-21">21</xref>]. Malicious nodes typically set the CW value to 1 or 2&#x2014;their study proved that when it is set to 1, the attacker can immediately access the channel without waiting for a backoff; however, when it is set to 2, other devices can access the channel first. Chakraborty et al. used backoff properties to address collisions during simultaneous transmissions; however, their algorithm did not work properly with large networks [<xref ref-type="bibr" rid="ref-24">24</xref>]. Nonetheless, their results demonstrated that a random-access game theoretical protocol exhibited higher average throughput and lower access delay compared to DCF in the case of WLAN. Odedra et al. combined threshold-based detection methods with watchdog surveillance techniques [<xref ref-type="bibr" rid="ref-23">23</xref>] to improve network performance and reduce the impact of selfish nodes. However, the proposed method was unable to detect cooperating selfish nodes and exhibited limited detection of the incapability of nodes to reengage in routing after isolation.</p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Jamming Attack</title>
<p>Jamming attacks are commonplace DoS attacks that cause intentional interference to stifle network communication [<xref ref-type="bibr" rid="ref-25">25</xref>]. Jammers are generally categorized as proactive or reactive, and the proactive type can be further divided into constant, deciphered, and random types [<xref ref-type="bibr" rid="ref-26">26</xref>].</p>
<p>Various studies have suggested methods for detecting and responding to deceptive jamming attacks, but few have suggested an integrated response system that distinguishes between selfish and jamming attack types. Vadlamani et al. conducted a survey and concluded that although a deceptive jammer is similar to a constant jammer, the former transmits a legitimate initial bit sequence to impersonate a legitimate node [<xref ref-type="bibr" rid="ref-27">27</xref>]. Deceptive versions also implement defense strategies against transmission power adjustment, frequency-hopping spread spectrum, channel switching, and directional antenna defenses.</p>
<p>Kanwar et al. proposed the JamSense model, which classifies and detects interference and jamming attacks in WLANs [<xref ref-type="bibr" rid="ref-28">28</xref>]. Their study distinguished between interference, constant jammers, and deceptive jammers. The authors classified the preamble and start-of-the-frame delimiters of the constant and deceptive jammers&#x2019; packets in terms of their transmission status. As such, attacks could be identified with up to 96% accuracy. Despite the excellent findings, the impact of these network attacks has not been analyzed further.</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Threat Detection and Response</title>
<p>Recent advancements in wireless network security have explored various mitigation frameworks aimed at enhancing system reliability and defense against adversarial threats. Liu et al. proposed the RFL-APIA framework, addressing federated learning vulnerabilities by identifying and mitigating model poisoning attacks through robust aggregation mechanisms, which parallels the proposed selective attack mitigation model&#x2019;s emphasis on adaptive response strategies in WSNs [<xref ref-type="bibr" rid="ref-29">29</xref>]. Bai et al. introduced a Throughput Maximization Model for secure multipath transmissions in wireless <italic>ad-hoc</italic> networks, focusing on optimizing network throughput while protecting from potential eavesdroppers [<xref ref-type="bibr" rid="ref-30">30</xref>]. Gong et al. explored Computation and Privacy Protection for Satellite-Ground Digital Twin Networks, emphasizing secure data mapping and resource optimization, an idea relevant to dynamic resource allocation in mitigating DoS attacks [<xref ref-type="bibr" rid="ref-31">31</xref>]. These works collectively underscore the necessity of adaptive, intelligent frameworks for real-time network threat detection and response, forming the conceptual basis for the proposed model&#x2019;s selective attack mitigation strategy.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>Key Features of IEEE 802.11</title>
<sec id="s3_1">
<label>3.1</label>
<title>DCF</title>
<p><xref ref-type="fig" rid="fig-1">Fig. 1</xref> presents typical infrastructure for WLAN, where wireless devices communicate with the AP within a coverage region. The underlying MAC mechanism of the IEEE 802.11 WLAN standard [<xref ref-type="bibr" rid="ref-32">32</xref>] is DCF, which uses competition-based algorithms to provide access to shared media [<xref ref-type="bibr" rid="ref-33">33</xref>]. As depicted in <xref ref-type="fig" rid="fig-2">Fig. 2</xref>, DCF adjusts channel access using the binary exponential backoff (BEB) algorithm [<xref ref-type="bibr" rid="ref-34">34</xref>], which prevents repeated retransmissions of the same packet to reduce network traffic [<xref ref-type="bibr" rid="ref-32">32</xref>]. If the sender detects an idle channel, it waits in the distributed interframe space (DIFS) and transmits its frame. If the channel is detected to be busy, the DIFS time is added to the backoff counter, and the packet is transmitted once the counter reaches zero. The backoff counter is an arbitrary time determined by the BEB and depends on the CW value. If the frame is successfully transmitted, the sender resets the CW value to the minimum value. If the frames collide, the CW is doubled to the maximum value, and a random backoff counter value is selected in [0, CW-1]. When the channel is found to be inactive, its value decreases. When the channel is used, the process is reactivated when the channel is inactive [<xref ref-type="bibr" rid="ref-35">35</xref>].</p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>Infrastructure of a WLAN system</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-1.tif"/>
</fig><fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>DCF mechanism</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-2.tif"/>
</fig>
<p>DCF uses two modes of transport&#x2014;basic (two-handshake) and RTS/CTS (four-handshake). In the basic mode, the sender detects whether the channel is busy and transmits a data frame if idle. Once the transmitted frame is received successfully, the receiver responds with an acknowledgement frame. The RTS/CTS access mode reserves a channel before data transmission. After receiving the frame, the other nodes update their NAV values based on the field duration of the RTS/CTS value of the reserved frame. The other nodes transmit data frames through the DCF when the NAV value reaches zero.</p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Multi-Link Operation</title>
<p>The IEEE 802.11be standard is expected to be an extremely high-throughput amendment to improve the reliability of wireless communications and increase the maximum throughput by 30 Gbps while reducing latency [<xref ref-type="bibr" rid="ref-36">36</xref>]. Multilink operations comprise the core technology needed to achieve these high expectations. The multilink framework is advantageous because it exhibits multifrequency bands and low hardware costs, such that APs and STAs can simultaneously transmit and receive information on different links using multiple radio interfaces depending on the transmission mode [<xref ref-type="bibr" rid="ref-37">37</xref>].</p>
<p>Multilink transmissions generally include synchronous and asynchronous methods categorized in terms of their simultaneous uplink/downlink (UL/DL) transmission capabilities. In both types, asynchronous transmissions and receptions on one or more links are allowed, and transmission on one link and reception on the other can be supported simultaneously. Additionally, DL frames that fail on one link can be retransmitted to other available links to reduce latency, and some traffic can be switched to other low-load links to improve the quality of service on overloaded links. During asynchronous operations, each link of the multilink device executes its channel process separately. Consequently, each link can achieve an independent maximum favorable throughput. In contrast, in synchronous operations, all links must wait for the idle state to begin transmission. Multiband and multichannel operations are discussed below in conjunction with multilink transmissions designed to improve performance despite heavy interference [<xref ref-type="bibr" rid="ref-35">35</xref>].</p>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Simulation Environment</title>
<p>NetSim v.13.1, a commercial IEEE 802.11-based packet-level network simulator, is used to simulate SAMM in this study. NetSim visualizes the WLAN packet flow, and a trace log is produced that reports the packet arrival time, queuing time, type, payload, overhead, status, and source. Before simulating the integrated DoS attack environment, a simplified WLAN environment containing one AP and 3&#x2013;10 connected STAs is modeled, as shown in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Simulation parameters</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Components</th>
<th>Parameters</th>
<th>Values</th>
</tr>
</thead>
<tbody>
<tr>
<td>Interface parameters</td>
<td>Standard</td>
<td>IEEE 802.11n</td>
</tr>
<tr>
<td></td>
<td>Number of packets aggregated</td>
<td>1</td>
</tr>
<tr>
<td></td>
<td>Channel</td>
<td>36 (5180 MHz)</td>
</tr>
<tr>
<td></td>
<td>Rate adaptation</td>
<td>FALSE</td>
</tr>
<tr>
<td></td>
<td>Short retry limit</td>
<td>7</td>
</tr>
<tr>
<td></td>
<td>Long retry limit</td>
<td>4</td>
</tr>
<tr>
<td></td>
<td>Dot11_RTS Threshold</td>
<td>800 bytes</td>
</tr>
<tr>
<td></td>
<td>Buffer size</td>
<td>1 MB</td>
</tr>
<tr>
<td></td>
<td>Guard interval</td>
<td>400 ns</td>
</tr>
<tr>
<td></td>
<td>Bandwidth</td>
<td>20/40 MHz</td>
</tr>
<tr>
<td></td>
<td>Frequency band</td>
<td>2.4/5 GHz</td>
</tr>
<tr>
<td></td>
<td>Transmitter power</td>
<td>100 mW</td>
</tr>
<tr>
<td></td>
<td>Antenna gain</td>
<td>0</td>
</tr>
<tr>
<td></td>
<td>Antenna height</td>
<td>1 m</td>
</tr>
<tr>
<td></td>
<td>Medium access protocol</td>
<td>DCF</td>
</tr>
<tr>
<td></td>
<td>SlotTime</td>
<td>9 us</td>
</tr>
<tr>
<td></td>
<td>SIFS</td>
<td>16 us</td>
</tr>
<tr>
<td></td>
<td>CS Min/Max</td>
<td>15/1023</td>
</tr>
<tr>
<td>Application parameters</td>
<td>Application</td>
<td>CBR</td>
</tr>
<tr>
<td></td>
<td>Packet size</td>
<td>1460 bytes</td>
</tr>
<tr>
<td></td>
<td>Inter-arrival time</td>
<td>11.6 &#x03BC;s</td>
</tr>
<tr>
<td>Link parameters</td>
<td>PathLoss model</td>
<td>Friis free space</td>
</tr>
<tr>
<td></td>
<td>Channel characteristics</td>
<td>PathLoss and fading and shadowing</td>
</tr>
<tr>
<td></td>
<td>Fading model</td>
<td>Rayleigh</td>
</tr>
<tr>
<td>Simulation parameters</td>
<td>Simulation time</td>
<td>10000 ms</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The environment is assumed to exhibit limited frame aggregation and rate adaptation. Hence, all interface parameters are selected based on the 802.11n standard, and the RTS_Threshold is set to 800 bytes to activate the RTS/CTS mechanism. Wireless nodes can generate a constant bit rate and file transfer protocol services using either the transmission control protocol or the user datagram protocol. The traffic generation rate is obtained as follows:
<disp-formula id="eqn-1"><label>(1)</label><mml:math id="mml-eqn-1" display="block"><mml:mi>C</mml:mi><mml:mi>B</mml:mi><mml:mi>R</mml:mi><mml:mi>G</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>R</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>P</mml:mi><mml:mi>a</mml:mi><mml:mi>c</mml:mi><mml:mi>k</mml:mi><mml:mi>e</mml:mi><mml:mi>t</mml:mi><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mi>z</mml:mi><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>b</mml:mi><mml:mi>y</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x00D7;</mml:mo><mml:mn>8</mml:mn></mml:mrow><mml:mrow><mml:mi>A</mml:mi><mml:mi>r</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>v</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>T</mml:mi><mml:mi>i</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>c</mml:mi><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac><mml:mo>,</mml:mo></mml:math></disp-formula>
<disp-formula id="eqn-2"><label>(2)</label><mml:math id="mml-eqn-2" display="block"><mml:mi>F</mml:mi><mml:mi>T</mml:mi><mml:mi>P</mml:mi><mml:mi>G</mml:mi><mml:mi>e</mml:mi><mml:mi>n</mml:mi><mml:mi>e</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>R</mml:mi><mml:mi>a</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>F</mml:mi><mml:mi>i</mml:mi><mml:mi>l</mml:mi><mml:mi>e</mml:mi><mml:mi>S</mml:mi><mml:mi>i</mml:mi><mml:mi>z</mml:mi><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>b</mml:mi><mml:mi>y</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x00D7;</mml:mo><mml:mn>8</mml:mn></mml:mrow><mml:mrow><mml:mi>A</mml:mi><mml:mi>r</mml:mi><mml:mi>r</mml:mi><mml:mi>i</mml:mi><mml:mi>v</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>T</mml:mi><mml:mi>i</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>c</mml:mi><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac><mml:mo>.</mml:mo></mml:math></disp-formula></p>
<p>Maximum packet and file sizes are set to 1460 bytes, and the inter-arrival time is unified at 11.6 &#x03BC;s. As the link and simulation parameters determine the wireless channel conditions and simulation time, models combining free-space path loss, shadowing, and Rayleigh fading are used for the simulation.</p>
<p>The network performance is illustrated in <xref ref-type="fig" rid="fig-3">Fig. 3</xref> in terms of the application and average link throughput. Link throughput considers all traffic passing through a link, including data and control packets, retransmissions, errors, and collisions. On the other hand, application throughput only considers the data packets successfully received at the destination from the source. Link throughput is calculated using <xref ref-type="disp-formula" rid="eqn-3">Eq. (3)</xref>, noting that an application throughput can be measured for each application. As depicted in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>, the maximum and minimum throughputs decrease as the number of STAs is increased. However, the link throughput is maintained at a constant value.</p>
<p><disp-formula id="eqn-3"><label>(3)</label><mml:math id="mml-eqn-3" display="block"><mml:mi>L</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mi>T</mml:mi><mml:mi>h</mml:mi><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>u</mml:mi><mml:mi>g</mml:mi><mml:mi>h</mml:mi><mml:mi>p</mml:mi><mml:mi>u</mml:mi><mml:mi>t</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>M</mml:mi><mml:mi>b</mml:mi><mml:mi>p</mml:mi><mml:mi>s</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:mi>o</mml:mi><mml:mi>t</mml:mi><mml:mi>a</mml:mi><mml:mi>l</mml:mi><mml:mi>b</mml:mi><mml:mi>y</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>s</mml:mi><mml:mi>t</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>t</mml:mi><mml:mi>t</mml:mi><mml:mi>e</mml:mi><mml:mi>d</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>t</mml:mi><mml:mi>h</mml:mi><mml:mi>e</mml:mi><mml:mi>l</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi><mml:mi>k</mml:mi><mml:mo>&#x00D7;</mml:mo><mml:mn>8</mml:mn></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:mi>r</mml:mi><mml:mi>a</mml:mi><mml:mi>n</mml:mi><mml:mi>s</mml:mi><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>s</mml:mi><mml:mi>s</mml:mi><mml:mi>i</mml:mi><mml:mi>o</mml:mi><mml:mi>n</mml:mi><mml:mi>T</mml:mi><mml:mi>i</mml:mi><mml:mi>m</mml:mi><mml:mi>e</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>c</mml:mi><mml:mi>r</mml:mi><mml:mi>o</mml:mi><mml:mi>s</mml:mi><mml:mi>e</mml:mi><mml:mi>c</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac><mml:mo>.</mml:mo></mml:math></disp-formula></p>

<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>Network performance of the WLAN simulation model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-3.tif"/>
</fig>
</sec>
<sec id="s5">
<label>5</label>
<title>Attack Models</title>
<sec id="s5_1">
<label>5.1</label>
<title>Selfish Attack Model</title>
<p><xref ref-type="fig" rid="fig-4">Fig. 4</xref> illustrates network performance as a function of the number of STAs during a selfish attack. The network&#x2019;s maximum application throughput is exceptionally high compared to a normal WLAN model because the maximum throughput is measured from the selfish node. Hence, the throughput of other nodes is diminished to values well below average minimum values. This increases the total bytes transmitted by the selfish node. Consequently, the average minimum application throughput of the other nodes is reduced from 2.96 to 0.28 Mbps, representing a 90.54% degradation in performance.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Network performance of the selfish attack model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-4.tif"/>
</fig>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Jamming Attack Model</title>
<p>A deceptive jammer is a type of radio frequency interference device that continuously transmits signals, similar to a constant jammer, but with a more sophisticated approach. Unlike constant jammers, which emit random noise or arbitrary bit sequences, deceptive jammers mimic legitimate communication signals. They transmit seemingly valid data packets or bit patterns that resemble those generated by legitimate devices in the network. Therefore, deceptive jamming attacks remain undetected for longer periods. Since their transmissions appear legitimate, distinguishing between real and fake data becomes challenging for the network. This tactic allows for prolonged disruption without immediate detection, making deceptive jammers more insidious and effective than constant jammers in denial-of-service (DoS) attacks. In addition, jammers adjust their signal strength to fine-tune their effects and avoid detection. <xref ref-type="fig" rid="fig-5">Fig. 5</xref> illustrates network performance as a function of the number of STAs during a jamming attack. <xref ref-type="table" rid="table-2">Table 2</xref> summarizes the simulation parameters, where the interaction time is used to determine the packet generation rate.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Network performance of jamming attack model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-5.tif"/>
</fig><table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Parameters for deceptive jammers</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Components</th>
<th>Parameters</th>
<th>Values</th>
</tr>
</thead>
<tbody>
<tr>
<td>Interface parameters</td>
<td>Standard</td>
<td>IEEE 802.11n</td>
</tr>
<tr>
<td></td>
<td>Number of packet aggregated</td>
<td>1</td>
</tr>
<tr>
<td></td>
<td>Channel</td>
<td>36 (5180 MHz)</td>
</tr>
<tr>
<td></td>
<td>Rate adaptation</td>
<td>FALSE</td>
</tr>
<tr>
<td></td>
<td>Short retry limit</td>
<td>7</td>
</tr>
<tr>
<td></td>
<td>Long retry limit</td>
<td>4</td>
</tr>
<tr>
<td></td>
<td>Dot11_RTS threshold</td>
<td>3000 bytes</td>
</tr>
<tr>
<td></td>
<td>Buffer size</td>
<td>1 MB</td>
</tr>
<tr>
<td></td>
<td>Guard interval</td>
<td>400 ns</td>
</tr>
<tr>
<td></td>
<td>Bandwidth</td>
<td>20/40 MHz</td>
</tr>
<tr>
<td></td>
<td>Frequency band</td>
<td>2.4/5 GHz</td>
</tr>
<tr>
<td></td>
<td>Transmitter power</td>
<td>100 mW</td>
</tr>
<tr>
<td></td>
<td>Antenna gain</td>
<td>0</td>
</tr>
<tr>
<td></td>
<td>Antenna height</td>
<td>1 m</td>
</tr>
<tr>
<td></td>
<td>Medium access protocol</td>
<td>DCF</td>
</tr>
<tr>
<td></td>
<td>SlotTime</td>
<td>9 &#x03BC;s</td>
</tr>
<tr>
<td></td>
<td>SIFS</td>
<td>16 &#x03BC;s</td>
</tr>
<tr>
<td></td>
<td>CS Min/Max</td>
<td>15/1023</td>
</tr>
<tr>
<td>Application parameters</td>
<td>Application</td>
<td>CBR</td>
</tr>
<tr>
<td></td>
<td>Packet size</td>
<td>8 bytes</td>
</tr>
<tr>
<td></td>
<td>Inter-arrival time</td>
<td>5.8 &#x03BC;s</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Notably, reducing the inter-arrival time increases this rate. To validate the proposed model, a jammer with a transmission power of 100 mW is positioned randomly, and 8-byte packets are transmitted at a rate calculated to achieve 5.8-&#x03BC;s inter-arrival times, resulting in &#x007E;17,241 packets generated per second. Because all nodes in the WLAN are capable of a robust 6.5-Mbps data rate, the STAs&#x2019; locations do not affect network performance significantly. In our simulation, the jammer follows the same standard as other STAs under normal circumstances. However, it also transmits periodic jamming packets without using the RTS/CTS mechanism. During the simulated attack, the number of packets transmitted to the AP is observed to be &#x007E;1000, disrupting its communications with other nodes. The attack is also observed to cause a loss of &#x007E;2000 data packets due to collision, whereas none typically crashed during normal WLAN operations. Thus, the jammer reduces the average throughput from 2.96 to 0.12 Mbps.</p>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Selective Attack Mitigation Model</title>
<sec id="s6_1">
<label>6.1</label>
<title>Dataset</title>
<p><xref ref-type="table" rid="table-3">Table 3</xref> summarizes the data used in this study based on packet log data collected in an attack-integrated model and a related description.</p>
<table-wrap id="table-3">
<label>Table 3</label>
<caption>
<title>Dataset components</title>
</caption>
<table>
<colgroup>
<col/>
<col/>
</colgroup>
<thead>
<tr>
<th>Feature</th>
<th>Description</th>
</tr>
</thead>
<tbody>
<tr>
<td>Queuing_Delay</td>
<td>Queuing time between time of arrival of the packet at PHY/MAC layer</td>
</tr>
<tr>
<td>Transmission_Time</td>
<td>Transmission duration between packet transmission in the link and arrival at the PHY layer of the transmitter</td>
</tr>
<tr>
<td>Propagation_Delay</td>
<td>Propagation delay time between packet transmission in the link and arrival at the PHY layer of the receiver</td>
</tr>
<tr>
<td>Total_Packet_Travelling_Time</td>
<td>Sum of queuing time, transmission time, and propagation delay time</td>
</tr>
<tr>
<td>isContinuoslyOccupied</td>
<td>Count if the packet type is a data packet and has the same source node as the previous one</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Packet trace log data, including type (data or control), source, destination, layer arrival time, payload size, collision status, queuing time, transmission time, propagation delay, total traveling time, and repetitions of communication occupancy, are simulated or collected from the attack model and compared with WLAN statistics in the absence of an attack.</p>
<p>Queuing delays are simulated by subtracting the time of arrival of the packet at the physical layer from that at the MAC layer [<xref ref-type="bibr" rid="ref-38">38</xref>]. The transmission time is simulated by subtracting the time of arrival of the packet at the physical layer from the time of initial transmission. The propagation delay is simulated by subtracting the time initial transmission time of the packet in the physical layer from the final transmission time in the physical layer. Finally, the total travel time is simulated by summing the queuing, transmission, and propagation delays.</p>
<p>Packets that monopolize communications with the AP and exhibit long durations are assumed to be related to attacks [<xref ref-type="bibr" rid="ref-26">26</xref>,<xref ref-type="bibr" rid="ref-28">28</xref>]. During model training, packet trace logs are analyzed to distinguish between attacks and ordinary packets, and the suspected attacks are classified as jamming or selfish attacks. The data are labeled by dividing the total number of transmitted packets by the number of packets obtained from the suspected jammer, the suspected selfish node, and normal packets.</p>
</sec>
<sec id="s6_2">
<label>6.2</label>
<title>Classification Algorithms</title>
<p><xref ref-type="fig" rid="fig-6">Fig. 6</xref> describes the proposed attack detection system pipeline, and Algorithm 1 is used to detect jamming and selfish attacks. <xref ref-type="fig" rid="fig-7">Fig. 7</xref> depicts the SAMM mechanism&#x2019;s attack mitigation pipeline. Unintentional continuous occupancy of a single STA with an AP can occur when a DCF mechanism is used with random backoff counters. However, a certain number of constant occupancies can be assumed to be non-coincidental [<xref ref-type="bibr" rid="ref-16">16</xref>]. In the proposed algorithm, the continuous occupancy of a packet that occurs more than thrice is considered to be an attack.</p>
<fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Attack detection pipeline of SAMM</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-6.tif"/>
</fig><fig id="fig-7">
<label>Figure 7</label>
<caption>
<title>Attack mitigation pipeline of SAMM</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-7.tif"/>
</fig>
<fig id="fig-11">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-11.tif"/>
</fig>
<p>The SAMM classification is based on a light gradient boosting machine (lightGBM) decision-tree model [<xref ref-type="bibr" rid="ref-38">38</xref>] with improved functionality, which exhibits high computation speeds with reduced memory consumption. Additionally, a normalization process is included to avoid overfitting. Using the GBDT boosting type, we trained the model with 400 iterative trees, each with a maximum of 31 leaves. The learning rate was set to 0.1, and the maximum depth of the trees was set to &#x2212;1. LightGBM is a highly efficient gradient-boosting framework that uses tree-based learning algorithms. Apart from other tree-based algorithms, It applies a more complex leaf-wise split approach to prevent overfitting [<xref ref-type="bibr" rid="ref-39">39</xref>]. In experiments comparing machine learning techniques, LightGBM had the fastest prediction time and model training time [<xref ref-type="bibr" rid="ref-40">40</xref>]. Due to deep learning generally requiring large volumes of labeled data to achieve optimal performance, SAMM applied a machine learning-based model requiring less labeled data for effective training.</p>
<p>The classification performance is evaluated in terms of accuracy and a binary confusion matrix that accounts for true-positive (TP), true-negative (TN), false-negative (FN), and false-positive (FP) predictions. Precision, Recall, F, and F1 scores are derived from these reports, where Precision &#x003D; TP/(TP &#x002B; FP), Recall &#x003D; TP/(TP &#x002B; FN), F score &#x003D; weighted average of precision and reproduction rates, and F1 score &#x003D; harmonic mean of precision and reproduction rates.</p>
</sec>
<sec id="s6_3">
<label>6.3</label>
<title>Count-Based Prediction</title>
<p>Although, the jamming node in a jamming attack may be unknown, the attacker is always obvious in a selfish attack. Hence, a count-based prediction algorithm is used to predict attacks using classified attack alarms while providing information on the suspected attacker node(s). Because multiclass classification algorithms detect attack types, accurate prediction based on the number of attack alarms is possible. In this paper, all predicted attack alarms are placed in a single section, and source-node ratios are calculated and compared.</p>
</sec>
<sec id="s6_4">
<label>6.4</label>
<title>Mitigation Techniques</title>
<p>Following detection and prediction using SAMM, a selective attack mitigation technique is used to respond selectively to the type of attack. In response to selfish attacks, the proposed mitigation system dynamically adjusts contention window (CW) values and backoff counters of non-attacking nodes to immediately reduce network degradation after identifying the attacker. By leveraging game-theoretic principles, the system minimizes control packet collisions during backoff counter reduction, ensuring efficient use of network resources. As illustrated in <xref ref-type="fig" rid="fig-8">Fig. 8</xref>, smaller CW values significantly enhance the average throughput of non-attacking nodes while increasing control packet collisions. This trade-off demonstrates the system&#x2019;s capability to maintain network performance even under attack conditions. Notably, decreasing the backoff counter values improves throughput for legitimate nodes. However, if the selfish node detects these adjustments and attempts to lower its backoff counter further, it can exacerbate network competition, causing widespread communication delays. To counter this, the system employs a final mitigation strategy: link switching. By virtually relocating the entire network&#x2014;excluding the attacker&#x2014;to a new channel, the system isolates the attacker, preserving the integrity and functionality of the legitimate network.</p>
<fig id="fig-8">
<label>Figure 8</label>
<caption>
<title>Comparative analysis of colliding control packets and average throughput with respect to CW values</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-8.tif"/>
</fig>
<p>In response to jamming attacks, the proposed mitigation model suggests adjusting the Receiver Sensitivity (RX sensitivity) and Clear Channel Assessment (CCA) threshold to reduce the impact of interference and maintain network performance. RX sensitivity refers to the minimum signal strength required at the receiver&#x2019;s antenna port to decode a signal accurately. Reducing RX sensitivity filters out weaker signals, such as those caused by the deceptive jammer, effectively decreasing its disruptive effects. On the other hand, increasing the CCA threshold allows devices to tolerate higher levels of background interference before deciding that the channel is occupied. This adjustment can enhance the ability of legitimate nodes to access the channel despite interference, improving throughput in dense environments. While CCA threshold adjustments primarily aim to mitigate interference rather than identify attackers, they play a crucial role in maintaining network stability by dynamically adapting to the jamming environment. Together, these techniques ensure robust mitigation against jamming attacks without compromising legitimate communication.</p>
</sec>
</sec>
<sec id="s7">
<label>7</label>
<title>Performance Evaluation</title>
<sec id="s7_1">
<label>7.1</label>
<title>Attack Response</title>
<p>A random forest-based anomaly detection model incapable of distinguishing between different attack type or average throughput of the nodes is simulated, and the results are compared with those of SAMM (<xref ref-type="fig" rid="fig-9">Fig. 9</xref>) [<xref ref-type="bibr" rid="ref-41">41</xref>]. The average node throughput and the number of out-of-service nodes (throughput &#x003D; 0) are measured during a simulated attack lasting 10 s. Applying the SAMM model is observed to reduce the number of out-of-service nodes significantly and maintain an average throughput of 2.69 Mbps, irrespective of the number of nodes. In comparison, the peak average throughput of the normal detection model is observed to be 0.61 Mbps with no mitigation actions. Notably, surplus nodes impact network performance due to collisions. However, throughput is observed to improve when more than five nodes are implemented in the proposed SAMM environment. Anomaly detection using random forest delivers high performance with a relatively high true positive rate, but for a large dataset, it requires a lot of computational power and leads to long training times. In comparison, the SAMM model provides fast learning by applying LGBM and higher detection accuracy compared to the conventional model by adding a multi-classification detection algorithm to classify attacks apart from normal communication.</p>
<fig id="fig-9">
<label>Figure 9</label>
<caption>
<title>Performance evaluation with respect to the number of nodes</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-9.tif"/>
</fig>
</sec>
<sec id="s7_2">
<label>7.2</label>
<title>Attack Detection</title>
<p><xref ref-type="fig" rid="fig-10">Fig. 10</xref> depicts the precision, recall, accuracy, and F1 score of SAMM and the ordinary anomaly detection model. Because the normal model assumes all packets apart from normal ones to be related to attacks, it achieves a precision of 100% but at the cost of a very high FN rate. Additionally, in the absence of an algorithm to determine attack types, it is incapable of mitigating network degradation despite exhibiting an accuracy of 82%. In contrast, SAMM achieves a classification accuracy of 96% and restores/retaines network performance successfully using mitigation techniques. In the experimental environment, the number of STAs was limited to 10, and a significant improvement in throughput was observed under these conditions. Although large-scale WSN environments were not tested, similar performance improvements are expected due to the adaptive nature of the proposed technique. Future research will focus on evaluating scalability and performance in large-scale WSN environments with resource-constrained devices.</p>
<fig id="fig-10">
<label>Figure 10</label>
<caption>
<title>Comparison of attack detection model</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CMC_58963-fig-10.tif"/>
</fig>
</sec>
</sec>
<sec id="s8">
<label>8</label>
<title>Conclusions</title>
<p>Wireless communication systems based on the DCF mechanism are vulnerable to competition-based selfish and jamming attacks. Dense overlapping WLANs are particularly susceptible to interference from hidden nodes and intentional DoS attacks. However, further research is required to develop multiple attack detection and response capabilities. The SAMM model proposed in this paper is demonstrably effective at detecting and responding to selfish and jamming attacks based on performance comparison with a standard anomaly detection model. Its accuracy is higher than that of the standard model by more than 14%, and it is capable of choosing and implementing accurate responses quickly by distinguishing between the two types of attacks. For example, it is observed to restore network performance to normal levels in response to a simulated selfish attack. Nevertheless, the simulation scenario considered in this study is limited because performance results depend on the calculation methods and thresholds used. Future works should attempt to further improve the accuracy of attack detection by including attack patterns that do not depend on a single threshold. Furthermore, the algorithm is to be developed to respond not only to selfish and jamming attacks but also to DoS attacks such as battery depletion attacks, which cause network performance degradation and compromise device availability. In real wireless communication environments, performance is easily degraded due to various interferences that disrupt normal communication beyond the attacks presented in this paper. Enhancing the SAMM algorithm to distinguish not only intentional selfish and jamming attacks but also unintentional interference, makes it possible to improve the performance of real wireless network environments.</p>
</sec>
</body>
<back>
<ack><title>Acknowledgement</title>
<p>None.</p>
</ack>
<sec>
<title>Funding Statement</title>
<p>This work was supported by the Ministry of Trade, Industry and Energy (MOTIE) under Training Industrial Security Specialist for High-Tech Industry (RS-2024-00415520) supervised by the Korea Institute for Advancement of Technology (KIAT), and the Ministry of Science and ICT (MSIT) under the ICT Challenge and Advanced Network of HRD (ICAN) Program (No. IITP-2022-RS-2022-00156310) supervised by the Institute of Information &#x0026; Communication Technology Planning &#x0026; Evaluation (IITP).</p>
</sec>
<sec>
<title>Author Contributions</title>
<p>Study conception and design: Soyoung Joo, So-Hyun Park, Il-Gu Lee; data collection: Hye-Yeon Shim, Ye-Sol Oh; analysis and interpretation of results: Soyoung Joo, So-Hyun Park, Hye-Yeon Shim, Ye-Sol Oh, Il-Gu Lee; draft manuscript preparation: Soyoung Joo, So-Hyun Park; Supervision: Il-Gu Lee; funding acquisition: Il-Gu Lee. All authors reviewed the results and approved the final version of the manuscript.</p>
</sec>
<sec sec-type="data-availability">
<title>Availability of Data and Materials</title>
<p>The data that support the findings of this study are available from the corresponding author upon reasonable request.</p>
</sec>
<sec>
<title>Ethics Approval</title>
<p>Not applicable.</p>
</sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Hasan</surname> <given-names>MZ</given-names></string-name>, <string-name><surname>Hanapi</surname> <given-names>ZM</given-names></string-name>, <string-name><surname>Hussain</surname> <given-names>MZ</given-names></string-name></person-group>. <article-title>Wireless sensor security issues on data link layer: a survey</article-title>. <source>Comput Mater Contin</source>. <year>2023</year>;<volume>75</volume>(<issue>2</issue>):<fpage>4065</fpage>&#x2013;<lpage>84</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmc.2023.036444</pub-id>.</mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Majid</surname> <given-names>M</given-names></string-name>, <string-name><surname>Habib</surname> <given-names>S</given-names></string-name>, <string-name><surname>Javed</surname> <given-names>AR</given-names></string-name>, <string-name><surname>Rizwan</surname> <given-names>M</given-names></string-name>, <string-name><surname>Srivastava</surname> <given-names>G</given-names></string-name>, <string-name><surname>Gadekallu</surname> <given-names>TR</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>Applications of wireless sensor networks and internet of things frameworks in the Industry Revolution 4.0: a systematic literature review</article-title>. <source>Sensors</source>. <year>2022</year>;<volume>22</volume>(<issue>6</issue>):<fpage>2087</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s22062087</pub-id>; <pub-id pub-id-type="pmid">35336261</pub-id></mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Landaluce</surname> <given-names>H</given-names></string-name>, <string-name><surname>Arjona</surname> <given-names>L</given-names></string-name>, <string-name><surname>Perallos</surname> <given-names>A</given-names></string-name>, <string-name><surname>Falcone</surname> <given-names>F</given-names></string-name>, <string-name><surname>Angulo</surname> <given-names>I</given-names></string-name>, <string-name><surname>Muralter</surname> <given-names>F</given-names></string-name></person-group>. <article-title>A review of IoT sensing applications and challenges using RFID and wireless sensor networks</article-title>. <source>Sensors</source>. <year>2020</year>;<volume>20</volume>(<issue>9</issue>):<fpage>2495</fpage>. doi:<pub-id pub-id-type="doi">10.3390/s20092495</pub-id>; <pub-id pub-id-type="pmid">32354063</pub-id></mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Angueira</surname> <given-names>P</given-names></string-name>, <string-name><surname>Val</surname> <given-names>I</given-names></string-name>, <string-name><surname>Montalban</surname> <given-names>J</given-names></string-name>, <string-name><surname>Seijo</surname> <given-names>&#x00D3;</given-names></string-name>, <string-name><surname>Iradier</surname> <given-names>E</given-names></string-name>, <string-name><surname>Fontaneda</surname> <given-names>PS</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>A survey of physical layer techniques for secure wireless communications in industry</article-title>. <source>IEEE Commun Surv Tutorials</source>. <year>2022</year>;<volume>24</volume>(<issue>2</issue>):<fpage>810</fpage>&#x2013;<lpage>38</lpage>. doi:<pub-id pub-id-type="doi">10.1109/COMST.2022.3148857</pub-id>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Aoki</surname> <given-names>T</given-names></string-name>, <string-name><surname>Li</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Pei</surname> <given-names>T</given-names></string-name>, <string-name><surname>Choi</surname> <given-names>Y-J</given-names></string-name>, <string-name><surname>Nguyen</surname> <given-names>K</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>Throughput analysis of IEEE 802.11 WLANs with inter-network interference</article-title>. <source>Appl Sci</source>. <year>2020</year>;<volume>10</volume>(<issue>6</issue>):<fpage>2192</fpage>. doi:<pub-id pub-id-type="doi">10.3390/app10062192</pub-id>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Edalat</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Obraczka</surname> <given-names>K</given-names></string-name>, <string-name><surname>Ahn</surname> <given-names>JS</given-names></string-name></person-group>. <article-title>Smart adaptive collision avoidance for IEEE 802.11</article-title>. <source>Ad Hoc Netw</source>. <year>2022</year>;<volume>124</volume>(<issue>3</issue>):<fpage>102721</fpage>. doi:<pub-id pub-id-type="doi">10.1016/j.adhoc.2021.102721</pub-id>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>CK</given-names></string-name>, <string-name><surname>Rhee</surname> <given-names>SH</given-names></string-name></person-group>. <article-title>Collision avoidance in IEEE 802.11 DCF using a reinforcement learning method</article-title>. In: <conf-name>2020 International Conference on Information and Communication Technology Convergence (ICTC)</conf-name>; <year>2020</year>; <publisher-loc>Jeju, Republic of Korea</publisher-loc>. p. <fpage>898</fpage>&#x2013;<lpage>901</lpage>.</mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Choi</surname> <given-names>WY</given-names></string-name></person-group>. <article-title>Fair MAC protocol for IEEE 802.11 wireless LANs with hidden node problem</article-title>. <source>J Electr Eng</source>. <year>2020</year>;<volume>71</volume>(<issue>5</issue>):<fpage>365</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.2478/jee-2020-0050</pub-id>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Bellardo</surname> <given-names>J</given-names></string-name>, <string-name><surname>Savage</surname> <given-names>S</given-names></string-name></person-group>. <article-title>802.11 denial-of-service attacks: real vulnerabilities and practical solutions</article-title>. In: <conf-name>12th USENIX Security Symposium (USENIX Security 03)</conf-name>; <year>2003</year>; <publisher-loc>Washington, DC, USA</publisher-loc>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Rath</surname> <given-names>M</given-names></string-name>, <string-name><surname>Mishra</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Advanced-level security in network and real-time applications using machine learning approaches</article-title>. In: <conf-name>Machine learning and cognitive science applications in cyber security</conf-name>. <publisher-loc>New York, NY, USA</publisher-loc>: <publisher-name>IGI Global</publisher-name>; <year>2022</year>. p. <fpage>84</fpage>&#x2013;<lpage>104</lpage>. doi:<pub-id pub-id-type="doi">10.4018/978-1-5225-8100-0.ch003</pub-id>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Thing</surname> <given-names>VL</given-names></string-name></person-group>. <article-title>IEEE 802.11 network anomaly detection and attack classification: a deep learning approach</article-title>. In: <conf-name>2017 IEEE Wireless Communications and Networking Conference (WCNC)</conf-name>; <year>2017</year>; <publisher-loc>San Francisco, CA, USA</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>6</lpage>.</mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Agarwal</surname> <given-names>M</given-names></string-name>, <string-name><surname>Pasumarthi</surname> <given-names>D</given-names></string-name>, <string-name><surname>Biswas</surname> <given-names>S</given-names></string-name>, <string-name><surname>Nandi</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Machine learning approach for detection of flooding DoS attacks in 802.11 networks and attacker localization</article-title>. <source>Int J Mach Learn Cybern</source>. <year>2016</year>;<volume>7</volume>(<issue>6</issue>):<fpage>1035</fpage>&#x2013;<lpage>51</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s13042-014-0309-2</pub-id>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Wang</surname> <given-names>N</given-names></string-name>, <string-name><surname>Jiao</surname> <given-names>L</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>P</given-names></string-name>, <string-name><surname>Li</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zeng</surname> <given-names>K</given-names></string-name></person-group>. <article-title>Machine learning-based spoofing attack detection in mmWave 60GHz IEEE 802.11 ad networks</article-title>. In: <conf-name>IEEE INFOCOM 2020-IEEE Conference on Computer Communications</conf-name>; <year>2020</year>; <publisher-loc>Toronto, ON, Canada</publisher-loc>. p. <fpage>2579</fpage>&#x2013;<lpage>88</lpage>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Upadhyaya</surname> <given-names>B</given-names></string-name>, <string-name><surname>Sun</surname> <given-names>S</given-names></string-name>, <string-name><surname>Sikdar</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Machine learning-based jamming detection in wireless IoT networks</article-title>. In: <conf-name>2019 IEEE VTS Asia Pacific Wireless Communications Symposium (APWCS)</conf-name>; <year>2019</year>; <publisher-loc>Singapore</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>5</lpage>.</mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Mamdouh</surname> <given-names>M</given-names></string-name>, <string-name><prefix>I</prefix> <surname>Elrukhsi</surname> <given-names>MA</given-names></string-name>, <string-name><surname>Khattab</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Securing the internet of things and wireless sensor networks via machine learning: a survey</article-title>. In: <conf-name>International Conference on Computer and Applications (ICCA)</conf-name>; <year>2018</year>; <publisher-loc>Beirut, Lebanon</publisher-loc>: <publisher-name>IEEE</publisher-name>. p. <fpage>215</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1109/COMAPP.2018.8460440</pub-id>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>R. Arunkumar</surname> <given-names>J</given-names></string-name>, <string-name><surname>Velmurugan</surname> <given-names>S</given-names></string-name>, <string-name><surname>Chinnaiah</surname> <given-names>B</given-names></string-name>, <string-name><surname>Charulatha</surname> <given-names>G</given-names></string-name>, <string-name><surname>Ramkumar Prabhu</surname> <given-names>M</given-names></string-name>, <string-name><surname>Prabhu Chakkaravarthy</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Logistic regression with elliptical curve cryptography to establish secure IoT</article-title>. <source>Comput Syst Sci Eng</source>. <year>2023</year>;<volume>45</volume>(<issue>3</issue>):<fpage>2635</fpage>&#x2013;<lpage>45</lpage>. doi:<pub-id pub-id-type="doi">10.32604/csse.2023.031605</pub-id>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Lee</surname> <given-names>YR</given-names></string-name>, <string-name><surname>Park</surname> <given-names>NE</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>SY</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>IG</given-names></string-name></person-group>. <article-title>Malicious traffic compression and classification technique for secure Internet of Things</article-title>. <source>Comput Mater Contin</source>. <year>2023</year>;<volume>76</volume>(<issue>3</issue>):<fpage>3465</fpage>&#x2013;<lpage>82</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmc.2023.041196</pub-id>.</mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Jeon</surname> <given-names>SE</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>SJ</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>EY</given-names></string-name>, <string-name><surname>Lee</surname> <given-names>YJ</given-names></string-name>, <string-name><surname>Ryu</surname> <given-names>JH</given-names></string-name>, <string-name><surname>Moon</surname> <given-names>JH</given-names></string-name>, <etal>et al</etal></person-group>. <article-title>An effective threat detection framework for advanced persistent cyberattacks</article-title>. <source>Comput Mater Contin</source>. <year>2023</year>;<volume>75</volume>(<issue>2</issue>):<fpage>4231</fpage>&#x2013;<lpage>53</lpage>. doi:<pub-id pub-id-type="doi">10.32604/cmc.2023.034287</pub-id>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Arafat</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yeaser</surname> <given-names>K</given-names></string-name>, <string-name><surname>Rahman</surname> <given-names>A</given-names></string-name>, <string-name><surname>Dasgupta</surname> <given-names>A</given-names></string-name></person-group>. <article-title>A machine learning based approach for protecting wireless networks against DoS Attacks</article-title>. In: <conf-name>Proceedings of the 7th International Conference on Networking, Systems and Security</conf-name>; <year>2020</year>; <publisher-loc>New York, NY, USA</publisher-loc>. p. <fpage>126</fpage>&#x2013;<lpage>32</lpage>. doi:<pub-id pub-id-type="doi">10.1145/3428363.3428377</pub-id>.</mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Konorski</surname> <given-names>J</given-names></string-name></person-group>. <article-title>A game-theoretic study of CSMA/CA under a backoff attack</article-title>. <source>IEEE ACM Trans Netw</source>. <year>2006</year>;<volume>14</volume>(<issue>6</issue>):<fpage>1167</fpage>&#x2013;<lpage>78</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TNET.2006.886298</pub-id>.</mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kim</surname> <given-names>J</given-names></string-name>, <string-name><surname>Kim</surname> <given-names>KS</given-names></string-name></person-group>. <article-title>Detecting selfish backoff attack in IEEE 802.15.4 CSMA/CA using logistic classification</article-title>. In: <conf-name>2018 Tenth International Conference on Ubiquitous and Future Networks (ICUFN)</conf-name>; <year>2018</year>; <publisher-loc>Prague, Czech Republic</publisher-loc>. p. <fpage>26</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ICUFN.2018.8436952</pub-id>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Odedra</surname> <given-names>L</given-names></string-name>, <string-name><surname>Revar</surname> <given-names>A</given-names></string-name>, <string-name><surname>Lunagaria</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Detection and prevention of selfish attack in MANET using dynamic learning</article-title>. <source>IOSR JCE</source>. <year>2016</year>;<volume>18</volume>(<issue>3</issue>):<fpage>54</fpage>&#x2013;<lpage>61</lpage>.</mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Fihri</surname> <given-names>WF</given-names></string-name>, <string-name><surname>Ghazi</surname> <given-names>HE</given-names></string-name>, <string-name><surname>Majd</surname> <given-names>BAE</given-names></string-name>, <string-name><surname>Bouanani</surname> <given-names>FE</given-names></string-name></person-group>. <article-title>A machine learning approach for backoff manipulation attack detection in cognitive radio</article-title>. <source>IEEE Access</source>. <year>2020</year>;<volume>8</volume>:<fpage>227349</fpage>&#x2013;<lpage>59</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ACCESS.2020.3046637</pub-id>.</mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Chakraborty</surname> <given-names>S</given-names></string-name>, <string-name><surname>Sanyal</surname> <given-names>DK</given-names></string-name>, <string-name><surname>Chattopadhyay</surname> <given-names>S</given-names></string-name></person-group>. <article-title>Performance of random access games over an IEEE 802.11ac test bed</article-title>. In: <conf-name>IEEE International Conference on Advanced Networks and Telecommunications Systems (ANTS)</conf-name>; <year>2019</year>; <publisher-loc>Goa, India</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>4</lpage>.</mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Xu</surname> <given-names>W</given-names></string-name>, <string-name><surname>Ma</surname> <given-names>K</given-names></string-name>, <string-name><surname>Trappe</surname> <given-names>W</given-names></string-name>, <string-name><surname>Zhang</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>Jamming sensor networks: attack and defense strategies</article-title>. <source>IEEE Netw</source>. <year>2006</year>;<volume>20</volume>(<issue>3</issue>):<fpage>41</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/MNET.2006.1637931</pub-id>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Djuraev</surname> <given-names>S</given-names></string-name>, <string-name><surname>Nam</surname> <given-names>SY</given-names></string-name></person-group>. <article-title>Channel-hopping-based jamming mitigation in wireless LAN considering throughput and fairness</article-title>. <source>Electronics</source>. <year>2020</year>;<volume>9</volume>(<issue>11</issue>):<fpage>1749</fpage>. doi:<pub-id pub-id-type="doi">10.3390/electronics9111749</pub-id>.</mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Vadlamani</surname> <given-names>S</given-names></string-name>, <string-name><surname>Eksioglu</surname> <given-names>B</given-names></string-name>, <string-name><surname>Medal</surname> <given-names>H</given-names></string-name>, <string-name><surname>Nandi</surname> <given-names>A</given-names></string-name></person-group>. <article-title>Jamming attacks on wireless networks: a taxonomic survey</article-title>. <source>Int J Prod Econ</source>. <year>2016</year>;<volume>172</volume>:<fpage>76</fpage>&#x2013;<lpage>94</lpage>. doi:<pub-id pub-id-type="doi">10.1016/j.ijpe.2015.11.008</pub-id>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Kanwar</surname> <given-names>J</given-names></string-name>, <string-name><surname>Finne</surname> <given-names>N</given-names></string-name>, <string-name><surname>Tsiftes</surname> <given-names>N</given-names></string-name>, <string-name><surname>Eriksson</surname> <given-names>J</given-names></string-name>, <string-name><surname>Voigt</surname> <given-names>T</given-names></string-name>, <string-name><surname>He</surname> <given-names>Z</given-names></string-name> <etal>et al</etal></person-group>. <article-title>JamSense: interference and jamming classification for low-power wireless networks</article-title>. In: <conf-name>13th IFIP Wireless and Mobile Networking Conference (WMNC)</conf-name>; <year>2021</year>; <publisher-loc>Montreal, QC, Canada</publisher-loc>. p. <fpage>9</fpage>&#x2013;<lpage>16</lpage>. doi:<pub-id pub-id-type="doi">10.23919/WMNC53478.2021.9619007</pub-id>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Liu</surname> <given-names>C</given-names></string-name>, <string-name><surname>He</surname> <given-names>A</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>G</given-names></string-name>, <string-name><surname>Wen</surname> <given-names>Y</given-names></string-name></person-group>. <article-title>RFL-APIA: a comprehensive framework for mitigating poisoning attacks and promoting model aggregation in IIoT federated learning</article-title>. <source>IEEE Trans Ind Inform</source>. <year>2024</year>;<volume>20</volume>(<issue>1</issue>):<fpage>123</fpage>&#x2013;<lpage>34</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TII.2024.3431020</pub-id>.</mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Bai</surname> <given-names>L</given-names></string-name>, <string-name><surname>Han</surname> <given-names>P</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>J</given-names></string-name></person-group>. <article-title>Throughput maximization for multipath secure transmission in wireless ad-hoc networks</article-title>. <source>IEEE Trans Wirel Commun</source>. <year>2024</year>;<volume>23</volume>(<issue>5</issue>):<fpage>987</fpage>&#x2013;<lpage>1002</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCOMM.2024.3409539</pub-id>.</mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Gong</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Yao</surname> <given-names>H</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>X</given-names></string-name>, <string-name><surname>Bennis</surname> <given-names>M</given-names></string-name></person-group>. <article-title>Computation and privacy protection for satellite-ground digital twin networks</article-title>. <source>IEEE Trans Commun</source>. <year>2024</year>;<volume>19</volume>(<issue>7</issue>):<fpage>2564</fpage>&#x2013;<lpage>78</lpage>. doi:<pub-id pub-id-type="doi">10.1109/TCOMM.2024.3392795</pub-id>.</mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Zerguine</surname> <given-names>N</given-names></string-name>, <string-name><surname>Aliouat</surname> <given-names>Z</given-names></string-name>, <string-name><surname>Mostefai</surname> <given-names>M</given-names></string-name>, <string-name><surname>Harous</surname> <given-names>S</given-names></string-name></person-group>. <article-title>M-BEB: enhanced and fair binary exponential backoff</article-title>. In: <conf-name>14th International Conference on Innovations in Information Technology (IIT)</conf-name>; <year>2020</year>; <publisher-loc>Al Ain, United Arab Emirates</publisher-loc>. p. <fpage>142</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/IIT50501.2020.9299014</pub-id>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Zhang</surname> <given-names>C</given-names></string-name>, <string-name><surname>Chen</surname> <given-names>P</given-names></string-name>, <string-name><surname>Ren</surname> <given-names>J</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Vasilakos</surname> <given-names>AV</given-names></string-name></person-group>. <article-title>A backoff algorithm based on self-adaptive contention window update factor for IEEE 802.11 DCF</article-title>. <source>Wirel Netw</source>. <year>2017</year>;<volume>23</volume>(<issue>3</issue>):<fpage>749</fpage>&#x2013;<lpage>58</lpage>. doi:<pub-id pub-id-type="doi">10.1007/s11276-015-1184-9</pub-id>.</mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Kobbaey</surname> <given-names>T</given-names></string-name>, <string-name><surname>Hamzaoui</surname> <given-names>R</given-names></string-name>, <string-name><surname>Ahmad</surname> <given-names>S</given-names></string-name>, <string-name><surname>Al-Fayoumi</surname> <given-names>M</given-names></string-name>, <string-name><surname>Thomos</surname> <given-names>N</given-names></string-name></person-group>. <article-title>Enhanced collision resolution and throughput analysis for the 802.11 distributed coordination function</article-title>. <source>Int J Commun Syst</source>. <year>2021</year>;<volume>34</volume>(<issue>16</issue>):<fpage>e4953</fpage>. doi:<pub-id pub-id-type="doi">10.1002/dac.4953</pub-id>.</mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Li</surname> <given-names>T</given-names></string-name>, <string-name><surname>Tang</surname> <given-names>T</given-names></string-name>, <string-name><surname>Chang</surname> <given-names>C</given-names></string-name></person-group>. <article-title>A new backoff algorithm for IEEE 802.11 distributed coordination function</article-title>. In: <conf-name>Sixth International Conference on Fuzzy Systems and Knowledge Discovery</conf-name>; <year>2009</year>; <publisher-loc>Tianjin, China</publisher-loc>. p. <fpage>455</fpage>&#x2013;<lpage>9</lpage>. doi:<pub-id pub-id-type="doi">10.1109/FSKD.2009.513</pub-id>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Deng</surname> <given-names>C</given-names></string-name>, <string-name><surname>Fang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Han</surname> <given-names>X</given-names></string-name>, <string-name><surname>Wang</surname> <given-names>X</given-names></string-name>, <string-name><surname>Yan</surname> <given-names>L</given-names></string-name>, <string-name><surname>He</surname> <given-names>R</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>IEEE 802.11be wi-fi 7: new challenges and opportunities</article-title>. <source>IEEE Commun Surv Tutorials</source>. <year>2020</year>;<volume>22</volume>(<issue>4</issue>):<fpage>2136</fpage>&#x2013;<lpage>66</lpage>. doi:<pub-id pub-id-type="doi">10.1109/COMST.2020.3012715</pub-id>.</mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>L&#x00F3;pez-Ravent&#x00F3;s</surname> <given-names>A</given-names></string-name>, <string-name><surname>Bellalta</surname> <given-names>B</given-names></string-name></person-group>. <article-title>Multi-link operation in IEEE 802.11be WLANs</article-title>. <source>IEEE Wireless Commun</source>. <year>2022</year>;<volume>29</volume>(<issue>4</issue>):<fpage>94</fpage>&#x2013;<lpage>100</lpage>. doi:<pub-id pub-id-type="doi">10.1109/MWC.006.2100404</pub-id>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="other"><person-group person-group-type="author"><string-name><surname>Seok</surname> <given-names>Y</given-names></string-name>, <string-name><surname>Tsao</surname> <given-names>W</given-names></string-name>, <string-name><surname>Bajko</surname> <given-names>G</given-names></string-name>, <string-name><surname>Yee</surname> <given-names>J</given-names></string-name>, <string-name><surname>Liu</surname> <given-names>J</given-names></string-name>, <string-name><surname>Cheng</surname> <given-names>P</given-names></string-name>, <etal>et al.</etal></person-group> <article-title>&#x2018;Enhanced multi-band/multi-channel operation,&#x2019; IEEE 802.11 documents</article-title>; <year>2019 May [cited 2024 Oct 20]</year>. Available from: <ext-link ext-link-type="uri" xlink:href="http://ieee.org/802.11/documents?is_dcn=0766&#x0026;is_group=00be">http://ieee.org/802.11/documents?is_dcn=0766&#x0026;is_group=00be</ext-link>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Islam</surname> <given-names>MK</given-names></string-name>, <string-name><surname>Hridi</surname> <given-names>P</given-names></string-name>, <string-name><surname>Hossain</surname> <given-names>MS</given-names></string-name>, <string-name><surname>Narman</surname> <given-names>HS</given-names></string-name></person-group>. <article-title>Network anomaly detection using lightgbm: a gradient boosting classifier</article-title>. In: <conf-name>2020 30th International Telecommunication Networks and Applications Conference (ITNAC)</conf-name>. <year>2020</year>; <publisher-loc>Melbourne, VIC, Australia</publisher-loc>: <publisher-name>IEEE</publisher-name>. p. <fpage>1</fpage>&#x2013;<lpage>7</lpage>. doi:<pub-id pub-id-type="doi">10.1109/ITNAC50341.2020.9315049</pub-id>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><surname>Seth</surname> <given-names>S</given-names></string-name>, <string-name><surname>Singh</surname> <given-names>G</given-names></string-name>, <string-name><surname>Chahal</surname> <given-names>KK</given-names></string-name></person-group>. <article-title>A novel time efficient learning-based approach for smart intrusion detection system</article-title>. <source>J Big Data</source>. <year>2021</year>;<volume>8</volume>(<issue>1</issue>):<fpage>111</fpage>. doi:<pub-id pub-id-type="doi">10.1186/s40537-021-00498-8</pub-id>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><surname>Elmrabit</surname> <given-names>N</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>F</given-names></string-name>, <string-name><surname>Li</surname> <given-names>F</given-names></string-name>, <string-name><surname>Zhou</surname> <given-names>H</given-names></string-name></person-group>. <article-title>Evaluation of machine learning algorithms for anomaly detection</article-title>. In: <conf-name>2020 International Conference on Cyber Security and Protection of Digital Services (Cyber Security)</conf-name>; <year>2020</year>; <publisher-loc>Dublin, Ireland</publisher-loc>. p. <fpage>1</fpage>&#x2013;<lpage>8</lpage>. doi:<pub-id pub-id-type="doi">10.1109/CyberSecurity49315.2020.9138871</pub-id>.</mixed-citation></ref>
</ref-list>
</back></article>